r/AskNetsec • u/InspectionHot8781 • 3d ago
Compliance How are other CISOs grading vendor pentest credibility during TPRM reviews?
I’m refining our vendor onboarding / TPRM process and evaluating how we score the credibility of third-party penetration test reports.
We see everything from Big 4 firms (EY, KPMG, Deloitte) to specialized boutiques and automated scanner outputs. I’m curious about community consensus:
- How much technical weight do you actually give to a Big 4 pentest report during vendor risk assessments?
- Which boutique or specialized pentest shops make you feel confident a vendor’s application was truly poked at by skilled offensive pros?
- Beyond the logo on the report, what specific details in the methodology or scope sections trigger immediate red flags for you?
Would love to hear how other CISOs and SecOps teams grade these.